> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anny.co/llms.txt
> Use this file to discover all available pages before exploring further.

# AI fact sheet: anny Agent

> Model, hosting, data processing, controls and legal classification of the anny Agent at a glance – for data protection, IT security and procurement.

This fact sheet summarizes the key technical and legal facts about the **anny Agent**. It is meant for data protection officers, IT security and procurement, and helps you with security questionnaires, data protection impact assessments and internal AI approvals. How to use the agent is described in [anny Agent](/en/anny-agent).

<Tip>
  The anny Agent is not anny AI on the phone or in the chat widget for your customers. anny AI is covered by the [anny AI addendum](https://anny.co/agreement-anny-ai) and uses its own sub-processors.
</Tip>

## At a glance

| | |
| - | - |
| **Product** | anny Agent, AI assistant in the admin (Admin 3.0) |
| **Users** | Users logged in to the admin, each with their own permissions |
| **AI model** | anny AI v1: a language model fine-tuned by anny on the basis of an open-source model (Qwen model family) |
| **Operation** | On infrastructure operated by anny, GPU servers at UpCloud (UpCloud Oy, Helsinki, Finland) |
| **Fallback** | If the own GPU servers are down or overloaded: Melious AI GmbH (Saarbrücken, Germany), with inference only at providers in the EU |
| **Processing location** | Data centers in the EU |
| **US providers** | None. No transfer to OpenAI or other US providers |
| **Training with customer data** | No |
| **Changes** | By default only after your approval |
| **Logging** | Every change in the record's activity, labeled **via AI Agent** |
| **Retention** | Conversation histories are deleted automatically after 90 days |
| **Costs** | Free during the beta, then a permanently free tier |

## Model and training

* **Base:** anny AI v1 builds on a freely available open-source language model. anny fine-tuned it for working in anny.
* **Training data:** For fine-tuning, anny used only scenarios it created itself. No real customer, booking or user data was used.
* **No use of your data:** Your messages, attachments, the agent's responses and the data in your account are not used to train or fine-tune AI models.

## What data the agent processes

| Data | When |
| - | - |
| Your messages and the agent's responses | Every time you use it |
| Attachments (images, screenshots, PDFs) | When you attach them |
| The page you are on | By default; **Don't send this page** leaves it out |
| Data in your account, e.g. resources, services, bookings, customer data, settings | When the agent looks it up for your request – only within your permissions |
| Executed actions with old and new value | With every change, in the [activity](/en/activity-log) |

As long as nobody writes to the agent, it does not process any data. Conversation histories are deleted automatically after 90 days.

## Control and security

* **Approval:** the default mode is **Ask first**. The agent shows you every change and waits for your go-ahead. In **Automatic** mode it applies changes without asking until you switch the mode off or reload the page. For settings of the whole organization and for actions that cannot be undone, it always asks.
* **Permissions:** the agent works in the account you are logged in to and can only do what your role allows you to do. It cannot extend permissions.
* **Tenant separation:** the agent only sees data of the organization you are logged in to.
* **Traceability:** every change, note and email from the agent appears with old and new value in the [activity](/en/activity-log) of the record.
* **Support:** if the agent gets stuck, it creates a support request for the anny team.
* **Off switch:** under **Apps & Integrations → anny Apps → anny Agent** you disable the agent for your whole organization. After that it no longer processes any data.

## Limits of AI

Responses, reports and suggestions from the agent are generated automatically. They can be incomplete, outdated or wrong. Check results before you use them for important or legally relevant decisions, and look at what changes before every approval.

## Legal classification

### Data protection (GDPR)

* **Roles:** for the data in your account, you are the controller and anny is the processor. The data processing agreement (DPA) between you and anny applies.
* **Sub-processors:** anny uses UpCloud to operate the GPU servers. As a fallback for outages or overload, anny uses Melious AI GmbH, Saarbrücken, Germany. Melious routes requests only to inference providers based in the EU. Both are listed as sub-processors in the DPA.

- **Third-country transfer:** the agent does not transfer data to countries outside the EU.
- **Automated decisions:** the agent does not make decisions within the meaning of Art. 22 GDPR. It prepares actions that you approve.
- **Privacy policy:** details are in [anny's privacy policy](https://anny.co/en/privacy).

### EU AI Act

* **Role:** anny is the provider of the AI system anny Agent. You use it as the deployer in your organization.
* **Risk class:** in anny's assessment, the anny Agent is not a high-risk AI system under Annex III. It is used to manage bookings, resources and settings.
* **Transparency:** the agent is clearly labeled as AI in the admin (**AI Agent**). Actions by the agent are marked **via AI Agent** in the activity.
* **Prohibited uses:** do not use the agent to make or prepare decisions about employees, about eligibility for public assistance benefits, or about access to educational institutions. The terms and conditions exclude these uses.
* **AI literacy:** as the deployer, you make sure your admins are familiar with the agent and its limits. This fact sheet and the [anny Agent](/en/anny-agent) article help you with that.

### Contractual basis

| Document | Content |
| - | - |
| [Terms and conditions](https://anny.co/terms), § 4a AI Features | Scope, approval, limits of AI, prohibited uses, no training |
| Data processing agreement (DPA) | Processing on your behalf, technical and organizational measures, sub-processors |
| [Privacy policy](https://anny.co/en/privacy) | Information for admin users |

## Questions

For security questionnaires, data protection impact assessments or questions from your data protection officer, contact our data protection team at [privacy@anny.co](mailto:privacy@anny.co). More about anny's security is in the [anny Trust Center](https://trust.anny.co/).

Fact sheet for the in-admin anny Agent (not the customer-facing anny AI phone/chat product). EN twin of `/anny-agent-datenblatt`. Confirmed facts: model anny AI v1, fine-tuned from an open-source Qwen-family model using only synthetic, anny-created scenarios; customer data is never used for training or fine-tuning; runs on anny-operated infrastructure with GPU servers at UpCloud (UpCloud Oy, Helsinki, Finland) in the EU; fallback on outage or overload: Melious AI GmbH (Saarbrücken), routing only to EU-based inference providers; no OpenAI or other US providers; no third-country transfer. Approval modes Ask first (default) / Automatic; organization settings and irreversible actions always ask. Works only with the logged-in user's permissions. Organization-wide off switch: Apps & Integrations → anny Apps → anny Agent. Chat histories are deleted automatically after 90 days. Legal: anny is processor (GDPR) and provider (EU AI Act); not a high-risk AI system per anny's assessment; terms § 4a applies from 2026-11-01.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.